作者投稿和查稿 主编审稿 专家审稿 编委审稿 远程编辑

计算机工程 ›› 2010, Vol. 36 ›› Issue (9): 150-152. doi: 10.3969/j.issn.1000-3428.2010.09.052

• 安全技术 • 上一篇    下一篇

基于网络驱动技术的木马通信检测系统

钟明全,李焕洲,唐彰国,张 健   

  1. (四川师范大学网络与通信技术研究所,成都 610066)
  • 收稿日期:1900-01-01 修回日期:1900-01-01 出版日期:2010-05-05 发布日期:2010-05-05

Trojan Communication Detection System Based on Network Drive Technology

ZHONG Ming-quan, LI Huan-zhou, TANG Zhang-guo, ZHANG Jian   

  1. (Institute of Network and Communication Technology, Sichuan Normal University, Chengdu 610066)
  • Received:1900-01-01 Revised:1900-01-01 Online:2010-05-05 Published:2010-05-05

摘要: 为提高木马程序的网络通信检测率,在比较各种包截获技术优缺点的基础上,设计并实现一种基于NDIS Hook驱动的木马通信检测系统,给出主要模块和数据结构,提出基于网络通信行为分析技术的木马通信识别模型。测试结果表明,该模型能降低误报率和漏报率,可截获所有网络通信数据包,识别新的木马通信。

关键词: 木马, 包截获, NDIS Hook驱动, 木马通信识别

Abstract: To enhance network communication detection of Trojan program, this paper designs and realizes a Trojan communication detection system based on NDIS Hook drive on the base of comparing advantages and disadvantages of various packet capture technology. It gives main modules and data structures, proposes Trojan communication identification model based on network communication behavior analysis technology. Test results show that this model can decrease false positive rate and negative positive rate, acquire all network communication data packet and identify new Trojan communication.

Key words: Trojan, packet capture, NDIS Hook drive, Trojan communication identification

中图分类号: